LogMan.io Integ

LogMan.io Integ allows LogMan.io to be integrated with supported external systems via expected message format and output/input protocol.

ArcSight

To connect LogMan.io with ArcSight, configure an instance of LogMan.io Integ in one of the following ways.

1) Passing parsed/correlated message

The following configuration JSON structure (correlated event etc.) to Syslog CEF.

# Set output

[pipeline:ArcSightPipeline:DatagramSink]
address=lm1:9999

# Set input

[connection:KafkaConnection]
bootstrap_servers=lm1:19092,lm2:29092,lm3:39092

[pipeline:ArcSightPipeline:KafkaSource]
topic=output
group_id=lmiointeg

## Specify timestamp field to add to the
## original JSON message (f. e. correlation or parsed log)
## to ArcSight input format (Syslog CEF)

[pipeline:ArcSightPipeline:ArcSightProcessor]
timestamp=end
dvc=127.0.0.1
dvchost=lm1

2) Passing original message

The following configuration transforms Syslog CEF to Syslog CEF.

# Set output

[pipeline:ArcSightPipeline:DatagramSink]
address=lm1:9999

# Set input

[connection:KafkaConnection]
bootstrap_servers=lm1:19092,lm2:29092,lm3:39092

[pipeline:ArcSightPipeline:KafkaSource]
topic=collected-cef
group_id=lmiointeg